spektr
spektr is a Danish compliance platform for regulated financial businesses. It combines configurable workflows with AI agents to automate KYC, KYB, transaction monitoring and case work, letting product, operations and compliance teams run the same system together.
What is spektr?
spektr is a compliance platform published by spektr ApS, a Copenhagen company selling to banks, fintechs, payment providers, marketplaces and digital-asset businesses. It presents itself as mission control for regulated businesses: one system where compliance sets the rules, product teams build the flows and operations runs them at scale.
The platform is organised around four products. Customer onboarding automates KYC, KYB and risk decisioning. Customer monitoring watches customers continuously and triggers a workflow when conditions change. Transaction monitoring surfaces transaction risk and applies risk-based routing with manual control where the team wants it. Case operations is where analysts resolve what reaches them. A policy engine sits underneath, so an institution's own written policies constrain what every process and every agent may do.
Four platform capabilities frame those products: connect your stack, automate processes, deploy AI and govern decisions. The connectors carry the most published detail. Around a hundred integrations are advertised and thirty have dedicated pages, covering national business registers such as Bolagsverket, Virk, Companies House, KRS, REGON, CEIDG, CRBR, BODACC and Data INPI, alongside identity and data providers including Veriff, Onfido, Scrive, MitID, BankID, itsme, Vipps, ComplyAdvantage, Creditsafe, Dun & Bradstreet, Kyckr and OpenCorporates.
The AI layer is a set of named agents rather than one assistant: KYB AI, Address AI, Industry AI, Licence AI, Source of Funds AI, Network Discovery AI, a website legitimacy checker, a document-review agent and a false-positives agent. They gather evidence, map ownership structures, resolve routine screening events and prepare cases, while the vendor is explicit that decisions needing human judgement stay with the team. Every action, approval and piece of evidence is written to a traceable record built for inspection.
A public REST API is documented on readme.io and authenticated with an x-api-key generated from the dashboard. spektr holds ISO 27001:2022, ISO 27701:2019 and ISO/IEC 42001:2023 certifications plus a SOC 2 Type II attestation, and states that data is hosted and handled within the EU. There is no self-service sign-up and no published pricing: access begins with a booked demo or a self-guided tour.
What it does
- Automate KYC and KYB onboarding, from data collection to a risk decision
- Monitor customers continuously and trigger a workflow when their risk profile changes
- Screen transactions for risk and route them according to policy
- Run AI agents that review documents, map ownership and resolve screening hits
- Build and change compliance workflows as configuration rather than code
- Enforce the institution's own written policies over every process and agent
- Record every action, approval and piece of evidence in an auditable log
When to use spektr / When not to
A quick filter to help you decide if spektr is the right fit.
When to use spektr
- Compliance and AML teams at banks and financial institutions that must run KYC, KYB and sanctions screening at scale
- Fintechs and payment providers that need to open new markets without waiting on an engineering release
- Marketplaces and platforms verifying business customers across several European jurisdictions
- Digital-asset and crypto businesses facing continuous customer and transaction monitoring duties
- Product and operations teams asked to own compliance workflows rather than file tickets for them
When not to use spektr
- Buyers who need a published price list, since nothing is disclosed before a sales conversation
- Small organisations with no AML, KYC or KYB obligations, which the platform is not built for
- Teams looking for a permanent free tier, as the demo is time-limited and leads to a paid version
- Users who need a mobile application, because the product ships as a web platform and an API only
- Teams that need a non-English product interface, which the vendor does not currently offer
How to use spektr
A typical end-to-end flow, from setup to results.
- Request access through the Book Demo or Talk To Us form, since there is no open sign-up
- Create a Demo Account; spektr may verify your details through third-party providers before granting access
- Explore the time-limited demo environment, remembering the vendor states its data is fictitious and not for decision-making
- Move to the paid version, which becomes necessary once the demo period expires
- Connect your sources: national registers, identity and data providers, CRM and internal systems
- Build your onboarding, monitoring, remediation, enrichment and scoring workflows as configuration
- Upload or author your own policies so the policy engine can hold processes and agents to them
- Deploy AI agents on the routine work and set where human review is required
- Generate an x-api-key from the dashboard settings page to integrate the API and event endpoints
- Monitor and optimise the agents in production, and review the audit log
Pros & Cons
Pros
- An unusually well-evidenced compliance posture: ISO 27001, ISO 27701 and ISO/IEC 42001 certifications plus a SOC 2 Type II attestation
- Data hosting and handling stated to take place within the EU
- Deep, individually documented connectors to European national business registers and identity providers
- Public API documentation reachable without an account
- Compliance logic configurable by the teams who own it, without a development cycle
- A visible release cadence, with change notes published continuously
- Named, verifiable reference customers including Santander Leasing, Pleo, Nexi, Monta and Mercuryo
Cons
- No public pricing at all: the site has no pricing page, so cost can only be obtained through sales
- No permanent free plan; the demo is time-limited and leads to the paid version
- The terms of service are generic and contradict themselves on ownership of customer contributions
- No customer-facing data processing agreement is published or offered on the site
- No list of subprocessors is published, despite a section on subprocessor governance
- The site never addresses whether customer data is used to train AI models
- No mobile application, and the product interface is English only
Pricing & Plans
No pricing is published. spektr operates on a quote basis: the site has no pricing page, and both /pricing and /plans return genuine 404 pages, so no entry-level amount or currency can be stated. There is no permanent free plan. The terms of service distinguish a time-limited Demo, reached through a booked demo or a self-guided tour, from a Paid Version that becomes necessary once the demo period expires. Prospective customers must contact the sales team for a figure.
Data, GDPR & hosting
A consolidated view of how spektr handles your data.
GDPR overview
GDPR implementation is documented in concrete terms. The controller is named as spektr ApS in Copenhagen, with privacy@spektr.com as the contact for data subject rights, and the policy invokes both the GDPR and the Danish Data Protection Act. It lists purposes, data categories and a legal basis for each processing activity, and sets out rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent. Transfers outside the EU and EEA are covered by standard contractual clauses. The supervisory authority named for complaints is the Danish Data Protection Agency, which is the regulator and not the vendor. spektr holds ISO 27701:2019 for privacy information management, alongside ISO 27001:2022, ISO/IEC 42001:2023 and a SOC 2 Type II attestation, and states it is GDPR compliant. A CCPA section addresses California residents.
Who owns the data?
The terms state that spektr asserts no ownership over customer contributions and that the customer retains full ownership of them and of the associated intellectual property rights. The same document, however, grants spektr an unrestricted, irrevocable, perpetual, worldwide, royalty-free licence to host, copy, disclose, sell, resell, publish and distribute those contributions. These two clauses sit in the same terms and are not reconciled. Separately, feedback sent to spektr is treated differently: all intellectual property rights in such submissions are assigned to the vendor. For client personal data, the trust page positions spektr as a processor acting only on documented instructions under GDPR Article 28.
Reuse rights
For the data a customer puts into the platform, the terms grant a licence to use the service for the customer's own internal business purpose only, and content and marks may not be copied, aggregated, republished, sold or otherwise exploited commercially without spektr's prior written permission. Reuse beyond that internal scope therefore does require asking. In the other direction, spektr states that client personal data is processed exclusively on documented instructions under GDPR Article 28, that it is never used for the vendor's own marketing or purposes, and that personal or company data is never sold. No page on the site addresses whether customer data is used to train AI models, in either direction.
Data retention & training
Hosting summary
spektr states on its homepage that all data is hosted and handled within the EU, and this is the only region-level commitment it makes. Two specific countries are named. The terms of service say the demo is hosted in Sweden and ask users accessing it from elsewhere to consent to that transfer. The privacy policy says the HubSpot account, used as the CRM, marketing automation and website analytics provider, is configured to store customer data within the European Union, in Germany, under a data processing agreement. Beyond those two, no hosting country is disclosed for the production platform and no infrastructure provider is named anywhere on the site. The privacy policy allows transfers outside the EU and EEA, protected by EU standard contractual clauses, recognised certification mechanisms or an adequacy decision, and a copy of the transfer basis can be requested. Encryption is claimed both at rest and in transit, and the vendor holds ISO 27001:2022 certification for its information security management system.
Things to keep in mind
Risks and trade-offs to weigh before adopting spektr.
- The terms of service contradict themselves on data ownership: they promise you keep full ownership of your contributions while granting spektr a perpetual, worldwide licence to sell, resell and publish them
- Anything you send as feedback is treated as a submission whose intellectual property rights you assign outright to the vendor
- No customer data processing agreement is published and no subprocessor list is disclosed, which is a gap for a vendor acting as a processor for regulated clients
- The site never states whether customer data is used to train AI models, so this must be settled contractually rather than assumed
- The privacy policy shows two different postcodes for the same registered office, a small sign that the legal pages are not closely maintained
- AML and CFT rules, KYB and KYC duties and the EU AI Act are what the software helps you comply with, and are obligations of its customers, not credentials of the vendor
- Automating analyst work can erode the in-house expertise needed to challenge an agent's output, so keeping meaningful human review is a real organisational risk
Setup & Integrations
Technical difficulty
Moderate to high, and not self-service. There is no open sign-up: onboarding runs through the sales team, then an integration phase connecting registers, identity providers, CRM and internal systems. The vendor's core argument is that business teams reconfigure flows without a development cycle, and changing a flow is presented as configuration rather than a release. That applies once the platform is wired in, however, not to the initial build. A public API supports deeper integration. The existence of spektrQ, a dedicated expert service for implementing and scaling these deployments, suggests the first setup is not trivial.
Deployment
Integrations
Supported languages
Behind spektr
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement spektr.
Frequently asked questions
What does spektr do?
Who publishes spektr?
How much does spektr cost?
Is there a free plan or a free trial?
Does spektr offer an API?
Where is the data hosted?
What certifications does spektr hold?
Is customer data used to train AI models?
What does spektr integrate with?
What languages does spektr support?
Should you pick spektr?
spektr is a credible, well-documented platform for a demanding niche: the compliance operations of banks, fintechs, marketplaces and digital-asset businesses in Europe. Its strongest and most verifiable asset is its own governance posture. Holding ISO 27001, ISO 27701 and ISO/IEC 42001 certifications together with a SOC 2 Type II attestation is uncommon, and the AI management certification is genuinely rare. Combined with a stated EU-only hosting position and an audit record covering every action and approval, this is a vendor that has clearly anticipated being inspected by its customers' regulators.
The product itself is substantial rather than promotional. The connector library is documented register by register, the AI agents are named and scoped to specific tasks instead of being sold as a general assistant, and the vendor is consistent that final judgement remains with a human analyst. A public API and a visible release cadence support the claim that this is a working platform rather than a pitch.
Two reservations deserve weight. The first is commercial opacity: there is no pricing page anywhere on the site, no plan structure and no entry-level figure, so no buyer can size the investment without engaging sales. The second is legal. The terms of service read as a generic template poorly fitted to a regulated B2B product, and they contradict themselves, telling the customer they retain full ownership of their contributions while granting spektr a perpetual, worldwide licence to sell and republish the same material. No customer data processing agreement is published, no subprocessor list is disclosed, and model training is never discussed. For an otherwise rigorous vendor, these are gaps worth raising directly before signing.
- Choosing a selection results in a full page refresh.
- Opens in a new window.